Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A user reports that their workstation displays a message demanding payment in Bitcoin to unlock files. The technician boots the computer into Safe Mode with Networking, but the ransom message still appears. What should the technician do next?

⚠ Common exam trap

Many exam-takers assume Safe Mode with Networking is sufficient to disable all malware, but file-encrypting ransomware can still run in Safe Mode if it has modified system files or uses kernel-level hooks, making an offline scan from a rescue disk the correct next step.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run a malware scanner in offline mode using a bootable rescue disk

The ransomware has likely encrypted the files and persists even in Safe Mode with Networking, indicating it may have modified system files or registry entries. Booting from a rescue disk and running an offline malware scanner allows the technician to scan the system without the ransomware actively running, as the malicious process is not loaded from the external media. This approach can remove the ransomware and potentially recover files, whereas reinstalling the OS would lose data and resetting browser settings is irrelevant to file-encrypting ransomware.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reinstall the operating system immediately

    Why it's wrong here

    Reinstalling the operating system immediately is a destructive last-resort action because it wipes the entire boot volume, including user data and any forensic artifacts needed to identify the ransomware variant or recover encrypted files. Reimaging also does not guarantee removal of malware embedded in other partitions, firmware, or external media, and it forfeits the chance to use recovery tools that might salvage encrypted data from Shadow Copies or file remnants. Proper incident response dictates isolating the system, preserving evidence, and attempting less destructive recovery methods first.

  • ✓

    Run a malware scanner in offline mode using a bootable rescue disk

    Why this is correct

    Running a malware scanner in offline mode using a bootable rescue disk is the correct next step because it bypasses the compromised operating system entirely, loading a trusted kernel and scanning the filesystem from outside the ransomware's control. In-guest scanners can be disabled, fooled, or subverted by rootkits or active malware that hooks system calls, whereas a bootable AV uses its own drivers and signature database to detect and remove persistent infections. Additionally, offline scanning identifies the specific ransomware strain, which may allow retrieval of a free decryptor or at least prevents further encryption by eliminating the payload.

  • ✗

    Reset the user's browser settings to default

    Why it's wrong here

    Resetting the user's browser settings to default is a browser-hijacker remediation, not a ransomware response. Ransomware is a system-level executable that typically encrypts files via the operating system's file I/O interfaces, independent of any browser state. While a malicious browser extension could theoretically download ransomware, the infection is already full-system at the point of the ransom demand, so resetting browser settings will not delete the executable, decrypt a single file, or stop the encryption process from recurring.

  • ✗

    Perform a system restore to a point before the infection

    Why it's wrong here

    Performing a system restore to a point before the infection is unreliable because modern ransomware variants routinely delete or encrypt restore points and the System Volume Information directory to block recovery via that mechanism. Even if a restore point survives, System Restore only reverts system files and registry settings—it does not decrypt user documents, images, or databases that the ransomware has already encrypted. Furthermore, if the malware persists in non-system partitions or as a bootkit, it may re-infect the system immediately after restore, making offline scanning a more robust approach.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.